CVE-2023-3102 – Insertion of Sensitive Information Into Sent Data in GitLab
https://notcve.org/view.php?id=CVE-2023-3102
A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows access to titles of private issue and MR. • https://gitlab.com/gitlab-org/gitlab/-/issues/414269 https://hackerone.com/reports/2012073 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-201: Insertion of Sensitive Information Into Sent Data •
CVE-2023-3484 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-3484
An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations. • https://about.gitlab.com/releases/2023/07/05/security-release-gitlab-16-1-2-released https://gitlab.com/gitlab-org/gitlab/-/issues/416773 https://hackerone.com/reports/2035687 • CWE-840: Business Logic Errors CWE-863: Incorrect Authorization •
CVE-2023-2620 – Insertion of Sensitive Information Into Sent Data in GitLab
https://notcve.org/view.php?id=CVE-2023-2620
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838. • https://gitlab.com/gitlab-org/gitlab/-/issues/410433 https://hackerone.com/reports/1976206 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-201: Insertion of Sensitive Information Into Sent Data •
CVE-2023-2576 – Incorrect Authorization in GitLab
https://notcve.org/view.php?id=CVE-2023-2576
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch. • https://gitlab.com/gitlab-org/gitlab/-/issues/410123 https://hackerone.com/reports/1898054 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •
CVE-2023-3362 – Generation of Error Message Containing Sensitive Information in GitLab
https://notcve.org/view.php?id=CVE-2023-3362
An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub. • https://gitlab.com/gitlab-org/gitlab/-/issues/415131 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-209: Generation of Error Message Containing Sensitive Information CWE-287: Improper Authentication •